Lucene search

K
prionPRIOn knowledge basePRION:CVE-2023-6542
HistoryDec 12, 2023 - 2:15 a.m.

Authorization

2023-12-1202:15:00
PRIOn knowledge base
www.prio-n.com
5
emarsys sdk
android
authorization checks
attacker
deep links

7.2 High

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

9.1%

Due to lack of proper authorization checks in Emarsys SDK for Android, an attacker can call a particular activity and can forward himself web pages and/or deep links without any validation directly from the host application. On successful attack, an attacker could navigate to arbitrary URL including application deep links on the device.

CPENameOperatorVersion
emarsys_sdkeq3.6.2

7.2 High

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

9.1%

Related for PRION:CVE-2023-6542